Virus

Résolu/Fermé
Profil bloqué - 19 févr. 2009 à 23:56
 Profil bloqué - 22 févr. 2009 à 13:54
Bonjour,
je viens d avoir un virus je vous fait mon rapport hijackthis pouvez vou m aider merci


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:54:21, on 19/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/?p=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S2BD.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [GTGMOUSE] "C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Startup: RockEnFolie le Player.lnk = C:\Program Files\RockEnFolie\RockEnFolie.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll (file missing)
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll (file missing)
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/installers/cab/SystemDoctor2006FreeInstall_fr.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - https://www.epson.eu/support/
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B194A0D-D7B5-4573-B482-4B0C3411C337}: NameServer = 192.168.1.1
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

89 réponses

Profil bloqué
20 févr. 2009 à 14:00
voila la suite


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
BIOS : Default System BIOS
USER : celine ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090219-0] 4.8.1335 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:36 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (CD or DVD)
J:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 20/02/2009|13:56 )

--------------------\\ Listing des dossiers dans APPLIC~1

[09/08/2007|19:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\ATI
[27/08/2006|12:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[14/09/2006|08:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[14/09/2006|08:25] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[14/09/2006|08:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
[14/09/2006|07:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver

[02/06/2008|08:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[25/08/2008|15:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[16/02/2009|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
[09/04/2007|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[30/10/2008|20:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[29/10/2008|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[16/10/2008|16:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[14/09/2006|08:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[17/09/2008|11:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[01/10/2008|21:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Knowledge Adventure
[30/03/2008|09:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[19/02/2009|23:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[07/08/2007|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MGI
[19/02/2009|23:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[18/09/2008|21:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\n7-89-o9-3r-4t-r9
[14/09/2006|07:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OD2
[16/08/2007|10:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[16/01/2009|19:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[19/02/2009|23:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[05/08/2007|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[10/08/2007|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SystemDoctor Free
[29/11/2008|19:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[29/09/2008|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[26/09/2008|15:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[14/09/2006|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\VadeRetro
[14/09/2006|07:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[28/01/2008|12:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Vivendi Universal Games
[18/01/2009|22:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\VUG
[21/08/2007|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[19/02/2009|23:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[19/02/2009|23:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[19/11/2007|15:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[18/09/2008|21:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[16/04/2008|18:50] C:\DOCUME~1\celine\APPLIC~1\Adobe
[02/06/2008|08:33] C:\DOCUME~1\celine\APPLIC~1\AdobeUM
[18/11/2007|23:19] C:\DOCUME~1\celine\APPLIC~1\Ahead
[09/08/2007|19:36] C:\DOCUME~1\celine\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\celine\APPLIC~1\ATI
[19/02/2009|23:37] C:\DOCUME~1\celine\APPLIC~1\Azureus
[08/01/2008|11:49] C:\DOCUME~1\celine\APPLIC~1\BitTorrent
[17/09/2008|17:30] C:\DOCUME~1\celine\APPLIC~1\cerasus.media
[24/01/2008|18:15] C:\DOCUME~1\celine\APPLIC~1\Chicken Chase
[09/04/2007|10:13] C:\DOCUME~1\celine\APPLIC~1\CyberLink
[07/10/2007|19:01] C:\DOCUME~1\celine\APPLIC~1\dvdcss
[29/10/2008|18:36] C:\DOCUME~1\celine\APPLIC~1\Flood Light Games
[16/10/2008|16:29] C:\DOCUME~1\celine\APPLIC~1\FloodLightGames
[16/08/2008|17:19] C:\DOCUME~1\celine\APPLIC~1\FUJIFILM
[18/09/2008|22:09] C:\DOCUME~1\celine\APPLIC~1\GameHouse
[10/02/2009|18:30] C:\DOCUME~1\celine\APPLIC~1\Google
[15/08/2007|18:00] C:\DOCUME~1\celine\APPLIC~1\Help
[27/10/2008|20:46] C:\DOCUME~1\celine\APPLIC~1\HiYo
[18/09/2008|21:42] C:\DOCUME~1\celine\APPLIC~1\Identities
[01/10/2007|11:43] C:\DOCUME~1\celine\APPLIC~1\Image Zone Express
[18/01/2009|22:18] C:\DOCUME~1\celine\APPLIC~1\InstallShield
[01/05/2007|20:43] C:\DOCUME~1\celine\APPLIC~1\InterTrust
[12/04/2007|09:27] C:\DOCUME~1\celine\APPLIC~1\Leadertech
[14/05/2007|17:22] C:\DOCUME~1\celine\APPLIC~1\Macromedia
[18/08/2008|15:01] C:\DOCUME~1\celine\APPLIC~1\Megaupload
[09/04/2007|09:49] C:\DOCUME~1\celine\APPLIC~1\MGI
[13/06/2008|17:49] C:\DOCUME~1\celine\APPLIC~1\Microsoft
[13/02/2009|13:52] C:\DOCUME~1\celine\APPLIC~1\Mozilla
[22/01/2009|22:25] C:\DOCUME~1\celine\APPLIC~1\MSN Pictures Displayer
[13/02/2009|13:52] C:\DOCUME~1\celine\APPLIC~1\Netscape
[10/04/2007|09:04] C:\DOCUME~1\celine\APPLIC~1\OD2
[13/02/2009|13:59] C:\DOCUME~1\celine\APPLIC~1\Photodex
[01/10/2007|11:43] C:\DOCUME~1\celine\APPLIC~1\Printer Info Cache
[14/09/2006|08:20] C:\DOCUME~1\celine\APPLIC~1\SampleView
[14/07/2008|17:19] C:\DOCUME~1\celine\APPLIC~1\Samsung
[30/09/2008|21:23] C:\DOCUME~1\celine\APPLIC~1\SecuROM
[12/04/2007|09:34] C:\DOCUME~1\celine\APPLIC~1\Sonic
[13/08/2007|15:01] C:\DOCUME~1\celine\APPLIC~1\Sun
[13/06/2008|15:11] C:\DOCUME~1\celine\APPLIC~1\Template
[18/02/2009|09:50] C:\DOCUME~1\celine\APPLIC~1\U3
[28/12/2007|23:34] C:\DOCUME~1\celine\APPLIC~1\uTorrent
[11/04/2007|14:48] C:\DOCUME~1\celine\APPLIC~1\VadeRetro
[18/06/2008|08:22] C:\DOCUME~1\celine\APPLIC~1\Viewpoint
[01/09/2007|15:18] C:\DOCUME~1\celine\APPLIC~1\vlc
[28/03/2008|17:37] C:\DOCUME~1\celine\APPLIC~1\WinPatrol
[25/08/2007|17:50] C:\DOCUME~1\celine\APPLIC~1\WinRAR
[14/09/2006|07:54] C:\DOCUME~1\celine\APPLIC~1\You've Got Pictures Screensaver
[18/09/2008|21:42] C:\DOCUME~1\celine\APPLIC~1\Zylom

[09/08/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI
[27/08/2006|12:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[14/09/2006|08:03] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[14/09/2006|08:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[14/09/2006|08:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[14/09/2006|07:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[09/08/2007|19:36] C:\DOCUME~1\fredo\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\fredo\APPLIC~1\ATI
[26/08/2007|10:18] C:\DOCUME~1\fredo\APPLIC~1\Help
[27/08/2006|12:04] C:\DOCUME~1\fredo\APPLIC~1\Identities
[21/08/2007|12:55] C:\DOCUME~1\fredo\APPLIC~1\Leadertech
[20/09/2007|14:16] C:\DOCUME~1\fredo\APPLIC~1\Macromedia
[20/01/2008|11:41] C:\DOCUME~1\fredo\APPLIC~1\Microsoft
[28/12/2007|15:09] C:\DOCUME~1\fredo\APPLIC~1\OD2
[14/09/2006|08:20] C:\DOCUME~1\fredo\APPLIC~1\SampleView
[21/08/2007|12:55] C:\DOCUME~1\fredo\APPLIC~1\Sonic
[26/08/2007|10:27] C:\DOCUME~1\fredo\APPLIC~1\VadeRetro
[17/11/2007|18:18] C:\DOCUME~1\fredo\APPLIC~1\vlc
[10/12/2007|15:04] C:\DOCUME~1\fredo\APPLIC~1\WinRAR
[14/09/2006|07:54] C:\DOCUME~1\fredo\APPLIC~1\You've Got Pictures Screensaver

[17/09/2007|11:53] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[07/01/2009|13:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\agi
[14/09/2006|07:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[14/09/2006|07:26] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[17/11/2008|17:37] C:\DOCUME~1\THIFFA~1\APPLIC~1\Adobe
[09/08/2007|19:36] C:\DOCUME~1\THIFFA~1\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\THIFFA~1\APPLIC~1\ATI
[17/11/2008|17:32] C:\DOCUME~1\THIFFA~1\APPLIC~1\EmailNotifier
[20/09/2007|14:25] C:\DOCUME~1\THIFFA~1\APPLIC~1\Help
[27/08/2006|12:04] C:\DOCUME~1\THIFFA~1\APPLIC~1\Identities
[10/04/2007|09:22] C:\DOCUME~1\THIFFA~1\APPLIC~1\Macromedia
[17/11/2008|17:32] C:\DOCUME~1\THIFFA~1\APPLIC~1\MEGAUPLOADTOOLBAR
[08/04/2007|16:02] C:\DOCUME~1\THIFFA~1\APPLIC~1\Microsoft
[14/09/2006|08:20] C:\DOCUME~1\THIFFA~1\APPLIC~1\SampleView
[05/12/2007|12:47] C:\DOCUME~1\THIFFA~1\APPLIC~1\WinRAR
[14/09/2006|07:54] C:\DOCUME~1\THIFFA~1\APPLIC~1\You've Got Pictures Screensaver

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[20/02/2009 13:22][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[27/12/2007 11:09][--ah-----] C:\WINDOWS\tasks\Microsoft_Hardware_Launch_setup_exe.job
[20/02/2009 08:32][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/03/2006 20:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[14/05/2008|17:26] C:\Program Files\7-Zip
[26/09/2008|15:00] C:\Program Files\ABBYY FineReader 6.0 Sprint
[01/05/2007|20:43] C:\Program Files\Adobe
[20/02/2009|13:50] C:\Program Files\Ad-remover
[19/02/2009|23:37] C:\Program Files\Adverts
[18/02/2009|15:11] C:\Program Files\AGI
[10/08/2007|13:04] C:\Program Files\Alwil Software
[20/01/2008|10:46] C:\Program Files\AnmSMP
[25/08/2008|15:12] C:\Program Files\AOL 9.0
[09/08/2007|19:36] C:\Program Files\AOL Compagnon
[28/01/2009|15:39] C:\Program Files\Atari
[09/08/2007|19:35] C:\Program Files\ATI Technologies
[24/07/2008|09:24] C:\Program Files\AVIConverter
[15/02/2009|18:37] C:\Program Files\AviSynth 2.5
[14/09/2006|07:41] C:\Program Files\AvRack
[28/01/2009|15:38] C:\Program Files\Barbie(TM)
[19/09/2008|09:11] C:\Program Files\Big City Aventure Sydney
[08/01/2008|11:54] C:\Program Files\BitTorrent
[09/04/2007|09:41] C:\Program Files\CAM-IN SUITE III
[06/01/2008|18:18] C:\Program Files\CCleaner
[19/02/2009|23:37] C:\Program Files\Circle Developement
[09/08/2007|19:36] C:\Program Files\ComPlus Applications
[09/08/2007|19:37] C:\Program Files\Controle Parental
[09/08/2007|19:33] C:\Program Files\Controle Parental(3)
[14/09/2006|08:02] C:\Program Files\CyberLink
[18/11/2007|11:34] C:\Program Files\DAEMON Tools
[18/11/2007|11:34] C:\Program Files\DaemonTools_WhenUSave_Installer
[08/10/2008|21:47] C:\Program Files\Deviens Miss France
[09/08/2007|19:36] C:\Program Files\directx
[04/10/2008|15:01] C:\Program Files\Disney Interactive
[18/01/2009|22:17] C:\Program Files\Easy iPod MP4 PSP 3GP
[03/09/2008|12:53] C:\Program Files\eChanblard
[27/05/2007|09:34] C:\Program Files\Eidos Interactive
[27/05/2007|12:28] C:\Program Files\Eko
[19/02/2009|18:12] C:\Program Files\eMule
[26/09/2008|15:02] C:\Program Files\epson
[15/02/2009|18:36] C:\Program Files\eRightSoft
[09/10/2008|15:24] C:\Program Files\F1lzr
[20/02/2009|13:51] C:\Program Files\Fichiers communs
[05/12/2008|16:01] C:\Program Files\FinePixViewer
[10/06/2008|13:59] C:\Program Files\GIMP-2.0
[22/09/2007|11:18] C:\Program Files\Google
[14/09/2006|08:09] C:\Program Files\Goto Software
[01/10/2007|10:52] C:\Program Files\HP
[18/01/2009|22:18] C:\Program Files\iMesh Applications
[29/09/2008|18:04] C:\Program Files\Iminent
[28/01/2009|15:39] C:\Program Files\InstallShield Installation Information
[27/05/2007|11:50] C:\Program Files\Intel
[11/02/2009|10:34] C:\Program Files\Internet Explorer
[09/08/2007|19:37] C:\Program Files\IrfanView
[26/03/2008|09:26] C:\Program Files\Java
[14/09/2006|07:54] C:\Program Files\Learn2.com
[15/11/2007|21:42] C:\Program Files\Livre Album Fuji Photo
[22/01/2008|17:55] C:\Program Files\LudoSoft
[17/09/2008|21:32] C:\Program Files\Mattel Interactive
[18/08/2008|15:00] C:\Program Files\Megaupload
[20/02/2009|11:17] C:\Program Files\Messenger
[19/02/2009|23:43] C:\Program Files\Messenger Plus! Live
[19/02/2009|23:36] C:\Program Files\MessengerPlus! 3
[07/08/2007|17:45] C:\Program Files\MGI
[28/01/2008|13:21] C:\Program Files\Micro Application
[21/12/2007|19:53] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/08/2006|12:04] C:\Program Files\microsoft frontpage
[20/08/2008|04:01] C:\Program Files\Microsoft LifeCam
[13/06/2008|17:46] C:\Program Files\Microsoft Office
[20/12/2007|16:06] C:\Program Files\Microsoft SQL Server Compact Edition
[10/09/2008|08:16] C:\Program Files\Microsoft Works
[02/10/2008|22:38] C:\Program Files\Mindscape
[22/08/2008|10:47] C:\Program Files\Movie Maker
[25/09/2008|14:17] C:\Program Files\Mozilla Firefox
[25/08/2007|16:45] C:\Program Files\MSECache
[10/04/2007|18:53] C:\Program Files\MSN
[27/08/2006|11:51] C:\Program Files\MSN Gaming Zone
[22/01/2009|22:25] C:\Program Files\MSN Pictures Displayer
[09/08/2007|19:36] C:\Program Files\MSXML 4.0
[30/03/2008|09:39] C:\Program Files\Navilog1
[18/11/2007|22:58] C:\Program Files\Nero
[22/08/2008|10:42] C:\Program Files\NetMeeting
[17/09/2008|11:24] C:\Program Files\Oberon Media
[21/02/2008|13:27] C:\Program Files\Omni
[27/08/2006|11:52] C:\Program Files\Online Services
[16/09/2008|16:13] C:\Program Files\orange
[22/08/2008|10:42] C:\Program Files\Outlook Express
[13/02/2009|13:52] C:\Program Files\Photodex
[19/02/2009|23:37] C:\Program Files\PhotoFiltre Studio
[25/11/2007|20:37] C:\Program Files\Picasa2
[28/01/2008|13:15] C:\Program Files\QuickTime
[14/09/2006|07:53] C:\Program Files\Real
[14/09/2006|07:41] C:\Program Files\Realtek AC97
[09/08/2007|19:36] C:\Program Files\Realtek Sound Manager
[29/09/2008|11:18] C:\Program Files\ReflexiveArcade
[16/08/2008|17:13] C:\Program Files\REGSHAVE
[27/06/2008|16:43] C:\Program Files\SAGEM
[09/08/2007|19:35] C:\Program Files\SAGEM(2)
[09/08/2007|19:33] C:\Program Files\SAGEM(3)
[01/10/2007|14:57] C:\Program Files\SAGEM(4)
[14/07/2008|17:23] C:\Program Files\Samsung
[03/08/2007|11:11] C:\Program Files\Securitoo
[02/10/2007|09:19] C:\Program Files\Services en ligne
[14/09/2006|08:03] C:\Program Files\Skype
[14/09/2006|08:04] C:\Program Files\Sonic
[19/02/2009|23:36] C:\Program Files\Spybot - Search & Destroy
[27/05/2007|11:50] C:\Program Files\Take 2 Interactive Software Europe
[25/04/2007|20:13] C:\Program Files\TLC-Edusoft
[11/02/2009|00:06] C:\Program Files\Trend Micro
[29/07/2007|16:57] C:\Program Files\Uninstall Information
[25/09/2007|09:33] C:\Program Files\VBW
[11/06/2008|20:51] C:\Program Files\VGP2
[01/09/2007|15:25] C:\Program Files\VideoLAN
[14/09/2006|07:53] C:\Program Files\Viewpoint
[30/10/2008|20:24] C:\Program Files\VirginMega
[18/02/2009|13:26] C:\Program Files\Vuze
[20/02/2009|13:55] C:\Program Files\Wanadoo
[17/10/2008|18:01] C:\Program Files\Windows Journal Viewer
[19/02/2009|23:36] C:\Program Files\Windows Live
[19/02/2009|23:36] C:\Program Files\Windows Live Favorites
[19/02/2009|23:36] C:\Program Files\Windows Live Toolbar
[21/08/2007|12:22] C:\Program Files\Windows Media Connect 2
[21/08/2007|12:22] C:\Program Files\Windows Media Player
[22/08/2008|10:42] C:\Program Files\Windows NT
[27/08/2006|11:51] C:\Program Files\Windows Plus
[18/11/2007|11:13] C:\Program Files\WinRAR
[27/08/2006|12:04] C:\Program Files\xerox
[17/10/2008|17:42] C:\Program Files\Yahoo!
[19/09/2008|11:15] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[02/06/2008|08:34] C:\Program Files\Fichiers communs\Adobe
[18/11/2007|22:58] C:\Program Files\Fichiers communs\Ahead
[09/08/2007|19:36] C:\Program Files\Fichiers communs\AOL
[09/08/2007|19:36] C:\Program Files\Fichiers communs\aolshare
[29/07/2007|09:13] C:\Program Files\Fichiers communs\Borland Shared
[14/09/2006|08:05] C:\Program Files\Fichiers communs\InstallShield
[14/09/2006|08:08] C:\Program Files\Fichiers communs\Java
[29/09/2008|13:25] C:\Program Files\Fichiers communs\Knowledge Adventure
[09/08/2007|19:33] C:\Program Files\Fichiers communs\MGI Shared
[10/04/2007|09:56] C:\Program Files\Fichiers communs\Micro Application Shared
[17/10/2008|18:01] C:\Program Files\Fichiers communs\Microsoft Shared
[27/08/2006|11:53] C:\Program Files\Fichiers communs\MSSoap
[17/10/2008|17:49] C:\Program Files\Fichiers communs\Nosibay
[14/09/2006|07:53] C:\Program Files\Fichiers communs\Nullsoft
[16/09/2008|16:13] C:\Program Files\Fichiers communs\Oberon Media
[09/08/2007|19:36] C:\Program Files\Fichiers communs\ODBC
[14/09/2006|07:53] C:\Program Files\Fichiers communs\Real
[25/08/2006|00:31] C:\Program Files\Fichiers communs\Services
[14/09/2006|08:04] C:\Program Files\Fichiers communs\Sonic Shared
[27/08/2006|13:47] C:\Program Files\Fichiers communs\SpeechEngines
[14/09/2006|08:04] C:\Program Files\Fichiers communs\SureThing Shared
[05/08/2007|11:29] C:\Program Files\Fichiers communs\Symantec Shared
[22/08/2008|10:41] C:\Program Files\Fichiers communs\System
[10/08/2007|12:23] C:\Program Files\Fichiers communs\SystemDoctor
[14/09/2006|08:04] C:\Program Files\Fichiers communs\TiVo Shared
[28/01/2008|12:53] C:\Program Files\Fichiers communs\Vivendi Universal Games
[19/11/2007|23:10] C:\Program Files\Fichiers communs\VUG
[20/12/2007|15:57] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 50 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\Program Files\Adverts
C:\Program Files\Circle Developement

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-20 13:57:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 913

--------------------\\ Recherche d'autres infections

--------------------\\ ROGUES ..

C:\DOCUME~1\ALLUSE~1\APPLIC~1\SystemDoctor Free
C:\PROGRA~1\FICHIE~1\SystemDoctor

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\celine\Bureau\dossier jeu pas touche\agatha christie\Death On The Nile\gameres\images\bonus_rosary\bead_crack.png


[F:24][D:0]-> C:\DOCUME~1\celine\Cookies
[F:153][D:20]-> C:\DOCUME~1\celine\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 20/02/2009|13:42 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 20/02/2009|13:59 - Option : [1]

--------------------\\ Fin du rapport a 13:59:12
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
20 févr. 2009 à 14:11
Très bien ...


dans l'ordre :


1- Télécharge OTMoveIt3 (de Old_Timer) sur ton Bureau.

http://oldtimer.geekstogo.com/OTMoveIt3.exe

! Déconnecte toi et ferme toutes tes applications en cours !

Double clique sur "OTMoveIt3.exe" pour ouvrir le prg .
Puis copie ce qui se trouve en citation ci-dessous,


:Processes
explorer.exe

:Services

:Reg

:Files
C:\Program Files\DaemonTools_WhenUSave_Installer 

:Commands
[purity]
[emptytemp]
[Reboot]



et colle le dans le cadre de gauche de OTMoveIt3 :
Paste Instructions for items to be moved.
(ne touche à rien d'autre !)

-> clique sur MoveIt! pour lancer la suppression.
-> laisse travailler l'outil ...

( Note : ton bureau va disparaitre puis réapparaitre, c'est normal .)

-> une fois finis , un petite fenêtre s'ouvre : clique sur " Yes " .

Ton PC va redémarrer de lui même ...

-->Poste le contenu du rapport qui se trouve dans le dossier "C:\_OTMoveIt\MovedFiles"
( " xxxx2008_xxxxxx.log " où les "x" correspondent au jour et à l'heure de l'utilisation ).


==========================

2- Va dans panneau de config/ajout et suppression de prg .
Regarde dans la liste si tu trouves un prg comme : " CID Help ", "Circle Developement" ou
"Adverts" --->si ils s'y trouvent , supprime les .


===========================

3- ! Déconnecte toi et ferme toutes tes applications en cours !

Relance Lop S&D ,

--->choisis cette fois l'option 2 ( nettoyage ) et valide ...

->ne touche à rien pendant que l'outil travail .


Une fois le scan terminer ,le Bloc-Notes contenant le rapport va s'ouvrir.
Poste ce rapport dans ta prochaine réponse + un nouveau rapport Hijackthis pour analyse ...

0
Profil bloqué
20 févr. 2009 à 14:13
pour te repondre o debut je copie le rapport???
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
20 févr. 2009 à 14:25
?????

rien compris lol ... ^^


0
Profil bloqué
20 févr. 2009 à 14:59
tu me di Double clique sur "OTMoveIt3.exe" pour ouvrir le prg .
Puis copie ce qui se trouve en citation ci-dessous,


je pren le rapport que j ai fait???
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Profil bloqué
20 févr. 2009 à 15:02
je vien de comprendre mdr excuse moi
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
20 févr. 2009 à 15:03
non !


pas le rapport que tu as fait mais uniquement ceci qui est en gras :


:Processes
explorer.exe

:Services

:Reg

:Files
C:\Program Files\DaemonTools_WhenUSave_Installer

:Commands
[purity]
[emptytemp]
[Reboot]





Tu as saisi ? ... ;)



0
Profil bloqué
20 févr. 2009 à 15:07
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Program Files\DaemonTools_WhenUSave_Installer moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_534.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02202009_150243

Files moved on Reboot...
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
C:\WINDOWS\temp\Perflib_Perfdata_534.dat moved successfully.
0
Profil bloqué
20 févr. 2009 à 15:10
apre dans panneau de config je n est pas cid,help circle developpement ou advert
0
Profil bloqué
20 févr. 2009 à 15:16
rapport lod


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
BIOS : Default System BIOS
USER : celine ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090219-0] 4.8.1335 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)
C:\ (Local Disk) - NTFS - Total:144 Go (Free:36 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (CD or DVD)
J:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 20/02/2009|15:11 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Program Files\Adverts
Supprime! - C:\Program Files\Circle Developement

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\Program Files\Viewpoint
Supprime! - C:\DOCUME~1\celine\APPLIC~1\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[09/08/2007|19:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\ATI
[27/08/2006|12:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[14/09/2006|08:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[14/09/2006|08:25] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[14/09/2006|08:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
[14/09/2006|07:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver

[02/06/2008|08:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[25/08/2008|15:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[16/02/2009|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
[09/04/2007|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[30/10/2008|20:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[29/10/2008|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Flood Light Games
[16/10/2008|16:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
[14/09/2006|08:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[17/09/2008|11:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
[01/10/2008|21:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Knowledge Adventure
[30/03/2008|09:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[19/02/2009|23:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[07/08/2007|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MGI
[19/02/2009|23:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[18/09/2008|21:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\n7-89-o9-3r-4t-r9
[14/09/2006|07:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OD2
[16/08/2007|10:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[16/01/2009|19:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[19/02/2009|23:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[05/08/2007|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[10/08/2007|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SystemDoctor Free
[29/11/2008|19:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[29/09/2008|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[26/09/2008|15:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[14/09/2006|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\VadeRetro
[28/01/2008|12:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Vivendi Universal Games
[18/01/2009|22:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\VUG
[21/08/2007|12:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[19/02/2009|23:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[19/02/2009|23:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[19/11/2007|15:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[18/09/2008|21:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

[16/04/2008|18:50] C:\DOCUME~1\celine\APPLIC~1\Adobe
[02/06/2008|08:33] C:\DOCUME~1\celine\APPLIC~1\AdobeUM
[18/11/2007|23:19] C:\DOCUME~1\celine\APPLIC~1\Ahead
[09/08/2007|19:36] C:\DOCUME~1\celine\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\celine\APPLIC~1\ATI
[19/02/2009|23:37] C:\DOCUME~1\celine\APPLIC~1\Azureus
[08/01/2008|11:49] C:\DOCUME~1\celine\APPLIC~1\BitTorrent
[17/09/2008|17:30] C:\DOCUME~1\celine\APPLIC~1\cerasus.media
[24/01/2008|18:15] C:\DOCUME~1\celine\APPLIC~1\Chicken Chase
[09/04/2007|10:13] C:\DOCUME~1\celine\APPLIC~1\CyberLink
[07/10/2007|19:01] C:\DOCUME~1\celine\APPLIC~1\dvdcss
[29/10/2008|18:36] C:\DOCUME~1\celine\APPLIC~1\Flood Light Games
[16/10/2008|16:29] C:\DOCUME~1\celine\APPLIC~1\FloodLightGames
[16/08/2008|17:19] C:\DOCUME~1\celine\APPLIC~1\FUJIFILM
[18/09/2008|22:09] C:\DOCUME~1\celine\APPLIC~1\GameHouse
[10/02/2009|18:30] C:\DOCUME~1\celine\APPLIC~1\Google
[15/08/2007|18:00] C:\DOCUME~1\celine\APPLIC~1\Help
[27/10/2008|20:46] C:\DOCUME~1\celine\APPLIC~1\HiYo
[18/09/2008|21:42] C:\DOCUME~1\celine\APPLIC~1\Identities
[01/10/2007|11:43] C:\DOCUME~1\celine\APPLIC~1\Image Zone Express
[18/01/2009|22:18] C:\DOCUME~1\celine\APPLIC~1\InstallShield
[01/05/2007|20:43] C:\DOCUME~1\celine\APPLIC~1\InterTrust
[12/04/2007|09:27] C:\DOCUME~1\celine\APPLIC~1\Leadertech
[14/05/2007|17:22] C:\DOCUME~1\celine\APPLIC~1\Macromedia
[18/08/2008|15:01] C:\DOCUME~1\celine\APPLIC~1\Megaupload
[09/04/2007|09:49] C:\DOCUME~1\celine\APPLIC~1\MGI
[13/06/2008|17:49] C:\DOCUME~1\celine\APPLIC~1\Microsoft
[13/02/2009|13:52] C:\DOCUME~1\celine\APPLIC~1\Mozilla
[22/01/2009|22:25] C:\DOCUME~1\celine\APPLIC~1\MSN Pictures Displayer
[13/02/2009|13:52] C:\DOCUME~1\celine\APPLIC~1\Netscape
[10/04/2007|09:04] C:\DOCUME~1\celine\APPLIC~1\OD2
[13/02/2009|13:59] C:\DOCUME~1\celine\APPLIC~1\Photodex
[01/10/2007|11:43] C:\DOCUME~1\celine\APPLIC~1\Printer Info Cache
[14/09/2006|08:20] C:\DOCUME~1\celine\APPLIC~1\SampleView
[14/07/2008|17:19] C:\DOCUME~1\celine\APPLIC~1\Samsung
[30/09/2008|21:23] C:\DOCUME~1\celine\APPLIC~1\SecuROM
[12/04/2007|09:34] C:\DOCUME~1\celine\APPLIC~1\Sonic
[13/08/2007|15:01] C:\DOCUME~1\celine\APPLIC~1\Sun
[13/06/2008|15:11] C:\DOCUME~1\celine\APPLIC~1\Template
[18/02/2009|09:50] C:\DOCUME~1\celine\APPLIC~1\U3
[28/12/2007|23:34] C:\DOCUME~1\celine\APPLIC~1\uTorrent
[11/04/2007|14:48] C:\DOCUME~1\celine\APPLIC~1\VadeRetro
[01/09/2007|15:18] C:\DOCUME~1\celine\APPLIC~1\vlc
[28/03/2008|17:37] C:\DOCUME~1\celine\APPLIC~1\WinPatrol
[25/08/2007|17:50] C:\DOCUME~1\celine\APPLIC~1\WinRAR
[14/09/2006|07:54] C:\DOCUME~1\celine\APPLIC~1\You've Got Pictures Screensaver
[18/09/2008|21:42] C:\DOCUME~1\celine\APPLIC~1\Zylom

[09/08/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI
[27/08/2006|12:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[14/09/2006|08:03] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
[14/09/2006|08:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[14/09/2006|08:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[14/09/2006|07:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[09/08/2007|19:36] C:\DOCUME~1\fredo\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\fredo\APPLIC~1\ATI
[26/08/2007|10:18] C:\DOCUME~1\fredo\APPLIC~1\Help
[27/08/2006|12:04] C:\DOCUME~1\fredo\APPLIC~1\Identities
[21/08/2007|12:55] C:\DOCUME~1\fredo\APPLIC~1\Leadertech
[20/09/2007|14:16] C:\DOCUME~1\fredo\APPLIC~1\Macromedia
[20/01/2008|11:41] C:\DOCUME~1\fredo\APPLIC~1\Microsoft
[28/12/2007|15:09] C:\DOCUME~1\fredo\APPLIC~1\OD2
[14/09/2006|08:20] C:\DOCUME~1\fredo\APPLIC~1\SampleView
[21/08/2007|12:55] C:\DOCUME~1\fredo\APPLIC~1\Sonic
[26/08/2007|10:27] C:\DOCUME~1\fredo\APPLIC~1\VadeRetro
[17/11/2007|18:18] C:\DOCUME~1\fredo\APPLIC~1\vlc
[10/12/2007|15:04] C:\DOCUME~1\fredo\APPLIC~1\WinRAR
[14/09/2006|07:54] C:\DOCUME~1\fredo\APPLIC~1\You've Got Pictures Screensaver

[17/09/2007|11:53] C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
[07/01/2009|13:22] C:\DOCUME~1\LOCALS~1\APPLIC~1\agi
[14/09/2006|07:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[14/09/2006|07:26] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[17/11/2008|17:37] C:\DOCUME~1\THIFFA~1\APPLIC~1\Adobe
[09/08/2007|19:36] C:\DOCUME~1\THIFFA~1\APPLIC~1\AOL
[09/08/2007|19:36] C:\DOCUME~1\THIFFA~1\APPLIC~1\ATI
[17/11/2008|17:32] C:\DOCUME~1\THIFFA~1\APPLIC~1\EmailNotifier
[20/09/2007|14:25] C:\DOCUME~1\THIFFA~1\APPLIC~1\Help
[27/08/2006|12:04] C:\DOCUME~1\THIFFA~1\APPLIC~1\Identities
[10/04/2007|09:22] C:\DOCUME~1\THIFFA~1\APPLIC~1\Macromedia
[17/11/2008|17:32] C:\DOCUME~1\THIFFA~1\APPLIC~1\MEGAUPLOADTOOLBAR
[08/04/2007|16:02] C:\DOCUME~1\THIFFA~1\APPLIC~1\Microsoft
[14/09/2006|08:20] C:\DOCUME~1\THIFFA~1\APPLIC~1\SampleView
[05/12/2007|12:47] C:\DOCUME~1\THIFFA~1\APPLIC~1\WinRAR
[14/09/2006|07:54] C:\DOCUME~1\THIFFA~1\APPLIC~1\You've Got Pictures Screensaver

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[20/02/2009 14:22][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[27/12/2007 11:09][--ah-----] C:\WINDOWS\tasks\Microsoft_Hardware_Launch_setup_exe.job
[20/02/2009 15:04][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/03/2006 20:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[14/05/2008|17:26] C:\Program Files\7-Zip
[26/09/2008|15:00] C:\Program Files\ABBYY FineReader 6.0 Sprint
[01/05/2007|20:43] C:\Program Files\Adobe
[20/02/2009|13:50] C:\Program Files\Ad-remover
[18/02/2009|15:11] C:\Program Files\AGI
[10/08/2007|13:04] C:\Program Files\Alwil Software
[20/01/2008|10:46] C:\Program Files\AnmSMP
[25/08/2008|15:12] C:\Program Files\AOL 9.0
[09/08/2007|19:36] C:\Program Files\AOL Compagnon
[28/01/2009|15:39] C:\Program Files\Atari
[09/08/2007|19:35] C:\Program Files\ATI Technologies
[24/07/2008|09:24] C:\Program Files\AVIConverter
[15/02/2009|18:37] C:\Program Files\AviSynth 2.5
[14/09/2006|07:41] C:\Program Files\AvRack
[28/01/2009|15:38] C:\Program Files\Barbie(TM)
[19/09/2008|09:11] C:\Program Files\Big City Aventure Sydney
[08/01/2008|11:54] C:\Program Files\BitTorrent
[09/04/2007|09:41] C:\Program Files\CAM-IN SUITE III
[06/01/2008|18:18] C:\Program Files\CCleaner
[09/08/2007|19:36] C:\Program Files\ComPlus Applications
[09/08/2007|19:37] C:\Program Files\Controle Parental
[09/08/2007|19:33] C:\Program Files\Controle Parental(3)
[14/09/2006|08:02] C:\Program Files\CyberLink
[18/11/2007|11:34] C:\Program Files\DAEMON Tools
[08/10/2008|21:47] C:\Program Files\Deviens Miss France
[09/08/2007|19:36] C:\Program Files\directx
[04/10/2008|15:01] C:\Program Files\Disney Interactive
[18/01/2009|22:17] C:\Program Files\Easy iPod MP4 PSP 3GP
[03/09/2008|12:53] C:\Program Files\eChanblard
[27/05/2007|09:34] C:\Program Files\Eidos Interactive
[27/05/2007|12:28] C:\Program Files\Eko
[19/02/2009|18:12] C:\Program Files\eMule
[26/09/2008|15:02] C:\Program Files\epson
[15/02/2009|18:36] C:\Program Files\eRightSoft
[09/10/2008|15:24] C:\Program Files\F1lzr
[20/02/2009|13:51] C:\Program Files\Fichiers communs
[05/12/2008|16:01] C:\Program Files\FinePixViewer
[10/06/2008|13:59] C:\Program Files\GIMP-2.0
[22/09/2007|11:18] C:\Program Files\Google
[14/09/2006|08:09] C:\Program Files\Goto Software
[01/10/2007|10:52] C:\Program Files\HP
[18/01/2009|22:18] C:\Program Files\iMesh Applications
[29/09/2008|18:04] C:\Program Files\Iminent
[28/01/2009|15:39] C:\Program Files\InstallShield Installation Information
[27/05/2007|11:50] C:\Program Files\Intel
[11/02/2009|10:34] C:\Program Files\Internet Explorer
[09/08/2007|19:37] C:\Program Files\IrfanView
[26/03/2008|09:26] C:\Program Files\Java
[14/09/2006|07:54] C:\Program Files\Learn2.com
[15/11/2007|21:42] C:\Program Files\Livre Album Fuji Photo
[22/01/2008|17:55] C:\Program Files\LudoSoft
[17/09/2008|21:32] C:\Program Files\Mattel Interactive
[18/08/2008|15:00] C:\Program Files\Megaupload
[20/02/2009|11:17] C:\Program Files\Messenger
[19/02/2009|23:43] C:\Program Files\Messenger Plus! Live
[19/02/2009|23:36] C:\Program Files\MessengerPlus! 3
[07/08/2007|17:45] C:\Program Files\MGI
[28/01/2008|13:21] C:\Program Files\Micro Application
[21/12/2007|19:53] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[27/08/2006|12:04] C:\Program Files\microsoft frontpage
[20/08/2008|04:01] C:\Program Files\Microsoft LifeCam
[13/06/2008|17:46] C:\Program Files\Microsoft Office
[20/12/2007|16:06] C:\Program Files\Microsoft SQL Server Compact Edition
[10/09/2008|08:16] C:\Program Files\Microsoft Works
[02/10/2008|22:38] C:\Program Files\Mindscape
[22/08/2008|10:47] C:\Program Files\Movie Maker
[25/09/2008|14:17] C:\Program Files\Mozilla Firefox
[25/08/2007|16:45] C:\Program Files\MSECache
[10/04/2007|18:53] C:\Program Files\MSN
[27/08/2006|11:51] C:\Program Files\MSN Gaming Zone
[22/01/2009|22:25] C:\Program Files\MSN Pictures Displayer
[09/08/2007|19:36] C:\Program Files\MSXML 4.0
[30/03/2008|09:39] C:\Program Files\Navilog1
[18/11/2007|22:58] C:\Program Files\Nero
[22/08/2008|10:42] C:\Program Files\NetMeeting
[17/09/2008|11:24] C:\Program Files\Oberon Media
[21/02/2008|13:27] C:\Program Files\Omni
[27/08/2006|11:52] C:\Program Files\Online Services
[16/09/2008|16:13] C:\Program Files\orange
[22/08/2008|10:42] C:\Program Files\Outlook Express
[13/02/2009|13:52] C:\Program Files\Photodex
[19/02/2009|23:37] C:\Program Files\PhotoFiltre Studio
[25/11/2007|20:37] C:\Program Files\Picasa2
[28/01/2008|13:15] C:\Program Files\QuickTime
[14/09/2006|07:53] C:\Program Files\Real
[14/09/2006|07:41] C:\Program Files\Realtek AC97
[09/08/2007|19:36] C:\Program Files\Realtek Sound Manager
[29/09/2008|11:18] C:\Program Files\ReflexiveArcade
[16/08/2008|17:13] C:\Program Files\REGSHAVE
[27/06/2008|16:43] C:\Program Files\SAGEM
[09/08/2007|19:35] C:\Program Files\SAGEM(2)
[09/08/2007|19:33] C:\Program Files\SAGEM(3)
[01/10/2007|14:57] C:\Program Files\SAGEM(4)
[14/07/2008|17:23] C:\Program Files\Samsung
[03/08/2007|11:11] C:\Program Files\Securitoo
[02/10/2007|09:19] C:\Program Files\Services en ligne
[14/09/2006|08:03] C:\Program Files\Skype
[14/09/2006|08:04] C:\Program Files\Sonic
[19/02/2009|23:36] C:\Program Files\Spybot - Search & Destroy
[27/05/2007|11:50] C:\Program Files\Take 2 Interactive Software Europe
[25/04/2007|20:13] C:\Program Files\TLC-Edusoft
[11/02/2009|00:06] C:\Program Files\Trend Micro
[29/07/2007|16:57] C:\Program Files\Uninstall Information
[25/09/2007|09:33] C:\Program Files\VBW
[11/06/2008|20:51] C:\Program Files\VGP2
[01/09/2007|15:25] C:\Program Files\VideoLAN
[30/10/2008|20:24] C:\Program Files\VirginMega
[18/02/2009|13:26] C:\Program Files\Vuze
[20/02/2009|15:10] C:\Program Files\Wanadoo
[17/10/2008|18:01] C:\Program Files\Windows Journal Viewer
[19/02/2009|23:36] C:\Program Files\Windows Live
[19/02/2009|23:36] C:\Program Files\Windows Live Favorites
[19/02/2009|23:36] C:\Program Files\Windows Live Toolbar
[21/08/2007|12:22] C:\Program Files\Windows Media Connect 2
[21/08/2007|12:22] C:\Program Files\Windows Media Player
[22/08/2008|10:42] C:\Program Files\Windows NT
[27/08/2006|11:51] C:\Program Files\Windows Plus
[18/11/2007|11:13] C:\Program Files\WinRAR
[27/08/2006|12:04] C:\Program Files\xerox
[17/10/2008|17:42] C:\Program Files\Yahoo!
[19/09/2008|11:15] C:\Program Files\Zylom Games

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[02/06/2008|08:34] C:\Program Files\Fichiers communs\Adobe
[18/11/2007|22:58] C:\Program Files\Fichiers communs\Ahead
[09/08/2007|19:36] C:\Program Files\Fichiers communs\AOL
[09/08/2007|19:36] C:\Program Files\Fichiers communs\aolshare
[29/07/2007|09:13] C:\Program Files\Fichiers communs\Borland Shared
[14/09/2006|08:05] C:\Program Files\Fichiers communs\InstallShield
[14/09/2006|08:08] C:\Program Files\Fichiers communs\Java
[29/09/2008|13:25] C:\Program Files\Fichiers communs\Knowledge Adventure
[09/08/2007|19:33] C:\Program Files\Fichiers communs\MGI Shared
[10/04/2007|09:56] C:\Program Files\Fichiers communs\Micro Application Shared
[17/10/2008|18:01] C:\Program Files\Fichiers communs\Microsoft Shared
[27/08/2006|11:53] C:\Program Files\Fichiers communs\MSSoap
[17/10/2008|17:49] C:\Program Files\Fichiers communs\Nosibay
[14/09/2006|07:53] C:\Program Files\Fichiers communs\Nullsoft
[16/09/2008|16:13] C:\Program Files\Fichiers communs\Oberon Media
[09/08/2007|19:36] C:\Program Files\Fichiers communs\ODBC
[14/09/2006|07:53] C:\Program Files\Fichiers communs\Real
[25/08/2006|00:31] C:\Program Files\Fichiers communs\Services
[14/09/2006|08:04] C:\Program Files\Fichiers communs\Sonic Shared
[27/08/2006|13:47] C:\Program Files\Fichiers communs\SpeechEngines
[14/09/2006|08:04] C:\Program Files\Fichiers communs\SureThing Shared
[05/08/2007|11:29] C:\Program Files\Fichiers communs\Symantec Shared
[22/08/2008|10:41] C:\Program Files\Fichiers communs\System
[10/08/2007|12:23] C:\Program Files\Fichiers communs\SystemDoctor
[14/09/2006|08:04] C:\Program Files\Fichiers communs\TiVo Shared
[28/01/2008|12:53] C:\Program Files\Fichiers communs\Vivendi Universal Games
[19/11/2007|23:10] C:\Program Files\Fichiers communs\VUG
[20/12/2007|15:57] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 54 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-20 15:13:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 913

--------------------\\ Recherche d'autres infections

--------------------\\ ROGUES ..

C:\DOCUME~1\ALLUSE~1\APPLIC~1\SystemDoctor Free
C:\PROGRA~1\FICHIE~1\SystemDoctor

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\celine\Bureau\dossier jeu pas touche\agatha christie\Death On The Nile\gameres\images\bonus_rosary\bead_crack.png


[F:16][D:0]-> C:\DOCUME~1\celine\Cookies
[F:245][D:20]-> C:\DOCUME~1\celine\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 20/02/2009|13:42 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 20/02/2009|13:59 - Option : [1]
3 - "C:\Lop SD\LopR_3.txt" - 20/02/2009|15:15 - Option : [2]

--------------------\\ Fin du rapport a 15:15:25
0
Profil bloqué
20 févr. 2009 à 15:18
rapport hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:17:14, on 20/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S2BD.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [GTGMOUSE] "C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/installers/cab/SystemDoctor2006FreeInstall_fr.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - https://www.epson.eu/support/
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B194A0D-D7B5-4573-B482-4B0C3411C337}: NameServer = 192.168.1.1
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
0
Profil bloqué
20 févr. 2009 à 15:18
voila g tout fai ceu ke tu ma demander...
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
20 févr. 2009 à 16:06
Oki ....


1- refais un coup de CCleaner ( registre compris ) .


=======================


2- Télécharge MalwareByte's :
ici http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebytes anti malware
ou ici : http://www.malwarebytes.org/mbam.php

* Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'instale ) et mets le à jour .

(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/ )

* Potasse le tuto pour te familiariser avec le prg :
https://forum.pcastuces.com/sujet.asp?f=31&s=3
( cela dis, il est très simple d'utilisation ).

! Déconnecte toi et ferme toutes applications en cours !

* Lance Malwarebyte's .

Fais un examen dit "Rapide" .

--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date),
accompagné d'un nouveau rapport hijackthis pour analyse ...



0
Profil bloqué
20 févr. 2009 à 16:23
rapport malware

Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1780
Windows 5.1.2600 Service Pack 3

20/02/2009 16:22:14
mbam-log-2009-02-20 (16-22-02).txt

Type de recherche: Examen rapide
Eléments examinés: 78483
Temps écoulé: 4 minute(s), 26 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 3
Fichier(s) infecté(s): 7

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> No action taken.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\Fichiers communs\SystemDoctor (Rogue.SystemDoctor) -> No action taken.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free (Rogue.SystemDoctor) -> No action taken.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data (Rogue.SystemDoctor) -> No action taken.

Fichier(s) infecté(s):
C:\Program Files\Fichiers communs\SystemDoctor\err.log (Rogue.SystemDoctor) -> No action taken.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\Abbr (Rogue.SystemDoctor) -> No action taken.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\ActivationCode (Rogue.SystemDoctor) -> No action taken.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\HOURS (Rogue.SystemDoctor) -> No action taken.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\ProductCode (Rogue.SystemDoctor) -> No action taken.
C:\Documents and Settings\celine\Application Data\Google\ckzty22913935.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\celine\Application Data\Google\msnkpl32.dll (Trojan.FakeAlert) -> No action taken.
0
Profil bloqué
20 févr. 2009 à 16:24
rapport hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:24:11, on 20/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\vVX1000.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S2BD.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [GTGMOUSE] "C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/installers/cab/SystemDoctor2006FreeInstall_fr.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - https://www.epson.eu/support/
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B194A0D-D7B5-4573-B482-4B0C3411C337}: NameServer = 192.168.1.1
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
20 févr. 2009 à 16:31
re,


pour Malwarebytes , il y a un soucis ^^

Soit tu ne m'as pas posté le bon rapport ( celui-ci fait APRES la suppression des fichiers infectés )

Soit tu n'as pas fait la suppression ( regarde le rapport que tu m'as donné : "-> No action taken " = aucune action faite ) . Dans ce cas la , il faut refaire la manipe et bien faire la suppression comme indiqué ...



0
Profil bloqué
20 févr. 2009 à 17:26
ok oui c bon je vien de voir ke j avai pas supprier je te met le rapport et j en fai un otre de hijackthis

Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1780
Windows 5.1.2600 Service Pack 3

20/02/2009 17:25:35
mbam-log-2009-02-20 (17-25-35).txt

Type de recherche: Examen rapide
Eléments examinés: 78483
Temps écoulé: 4 minute(s), 26 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 3
Fichier(s) infecté(s): 7

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\Fichiers communs\SystemDoctor (Rogue.SystemDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free (Rogue.SystemDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data (Rogue.SystemDoctor) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Program Files\Fichiers communs\SystemDoctor\err.log (Rogue.SystemDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\Abbr (Rogue.SystemDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\ActivationCode (Rogue.SystemDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\HOURS (Rogue.SystemDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\ProductCode (Rogue.SystemDoctor) -> Quarantined and deleted successfully.
C:\Documents and Settings\celine\Application Data\Google\ckzty22913935.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\celine\Application Data\Google\msnkpl32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
0
Profil bloqué
20 févr. 2009 à 17:27
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:27:08, on 20/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\vVX1000.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S2BD.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [GTGMOUSE] "C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - https://www.epson.eu/support/
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B194A0D-D7B5-4573-B482-4B0C3411C337}: NameServer = 192.168.1.1
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
0
sKe69 Messages postés 21360 Date d'inscription samedi 15 mars 2008 Statut Contributeur sécurité Dernière intervention 30 décembre 2012 463
20 févr. 2009 à 17:36
bien ...


dans l'ordre :


1- Supprimes tout ce qui ce trouve dans la quarantaine de Malwarebytes .


========================


2- Refais un coup de CCleaner ( registre compris ) .


========================

3- Télécharge ComboFix (par sUBs) sur ton Bureau (et pas ailleurs !):

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


--------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
!! Déconnecte toi,ferme tes applications en cours ( ainsi que ton navigateur ) et DESACTIVE TOUTES TES DEFENSES (anti-virus, guarde anti spy-ware, pare-feu) le temps de la manipe :
en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
--->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
Tuto ( aide ) ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Note : pour XP, bien installer la Console de Récupération de Windows comme il est indiqué dans le tuto ci-dessus ...
---------------------------------------------------------------------------------------------------------------------------------

Ensuite :
double-clique sur l'icône "combofix.exe" pour lancer l'outil .

Appuie sur la touche Y (Yes) pour démarrer le scan .

Notes importantes :
-> n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
-> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisse le faire .
-> Si l'outil t'anonce ceci : "combofix a détecté la présence de rootkit et a besoin de faire redémarer votre machine", tu acceptes ...
-> si un message d'erreur windows apparait à un momment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

Le rapport sera crée ici : C:\Combofix.txt

Réactive bien tes défenses .


Poste le rapport Combofix accompagné d'un nouveau rapport hijackthis pour analyse ...



0
Profil bloqué
20 févr. 2009 à 18:05
rapport combofix

ComboFix 09-02-19.01 - celine 2009-02-20 18:00:20.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.959.512 [GMT 1:00]
Lancé depuis: c:\documents and settings\celine\Bureau\combofix.exe
AV: avast! antivirus 4.8.1335 [VPS 090219-0] *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Un nouveau point de restauration a été créé
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\AVSredirect.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-20 au 2009-02-20 ))))))))))))))))))))))))))))))))))))
.

2009-02-20 16:15 . 2009-02-20 16:15 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-20 16:15 . 2009-02-20 16:15 <REP> d-------- c:\documents and settings\celine\Application Data\Malwarebytes
2009-02-20 16:15 . 2009-02-20 16:15 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-20 16:15 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-20 16:15 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-20 15:02 . 2009-02-20 15:02 <REP> d-------- C:\_OTMoveIt
2009-02-20 13:38 . 2009-02-20 15:15 <REP> d-------- C:\Lop SD
2009-02-20 12:24 . 2009-02-20 17:29 <REP> d-------- c:\program files\Ad-remover
2009-02-20 11:31 . 2009-02-20 11:34 <REP> d-------- C:\ToolBar SD
2009-02-19 23:36 . 2009-02-19 23:36 <REP> d-------- c:\program files\Windows Live Favorites
2009-02-19 23:36 . 2009-02-19 23:36 <REP> d-------- c:\program files\MessengerPlus! 3
2009-02-19 23:36 . 2009-02-19 23:36 <REP> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-19 23:02 . 2009-02-19 23:02 <REP> d-------- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-02-18 15:10 . 2009-02-18 15:11 <REP> d-------- c:\program files\AGI
2009-02-18 12:53 . 2009-02-18 12:53 45 ---h----- c:\windows\dsez9197.dat
2009-02-18 12:52 . 2009-02-19 23:37 <REP> d-------- c:\program files\PhotoFiltre Studio
2009-02-16 13:44 . 2009-02-19 23:37 <REP> d-------- c:\documents and settings\celine\Application Data\Azureus
2009-02-16 13:44 . 2009-02-16 13:44 <REP> d-------- c:\documents and settings\All Users\Application Data\Azureus
2009-02-16 13:43 . 2009-02-18 13:26 <REP> d-------- c:\program files\Vuze
2009-02-15 18:37 . 2009-02-15 18:37 <REP> d-------- c:\program files\AviSynth 2.5
2009-02-15 18:36 . 2009-02-15 18:36 <REP> d-------- c:\program files\eRightSoft
2009-02-13 13:52 . 2009-02-13 13:52 <REP> d-------- c:\program files\Photodex
2009-02-13 13:52 . 2009-02-13 13:52 <REP> d-------- c:\documents and settings\celine\Application Data\Netscape
2009-02-13 13:48 . 2009-02-13 13:59 <REP> d-------- c:\documents and settings\celine\Application Data\Photodex
2009-02-11 00:06 . 2009-02-11 00:06 <REP> d-------- c:\program files\Trend Micro
2009-01-22 22:25 . 2009-01-22 22:25 <REP> d-------- c:\documents and settings\celine\Application Data\MSN Pictures Displayer
2009-01-22 22:25 . 2009-01-22 22:25 446,976 --a------ c:\windows\system32\ShellMPD.dll
2009-01-22 22:24 . 2009-01-22 22:25 <REP> d-------- c:\program files\MSN Pictures Displayer

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-20 16:57 --------- d-----w c:\program files\Wanadoo
2009-02-20 14:32 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-19 22:36 --------- d-----w c:\program files\Windows Live Toolbar
2009-02-19 22:36 --------- d-----w c:\program files\Windows Live
2009-02-19 22:36 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-19 22:36 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-19 22:14 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-02-19 17:12 --------- d-----w c:\program files\eMule
2009-02-18 08:50 --------- d-----w c:\documents and settings\celine\Application Data\U3
2009-01-28 14:39 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-28 14:39 --------- d-----w c:\program files\Atari
2009-01-28 14:38 --------- d-----w c:\program files\Barbie(TM)
2009-01-18 21:18 --------- d-----w c:\program files\iMesh Applications
2009-01-18 21:18 --------- d-----w c:\documents and settings\celine\Application Data\InstallShield
2009-01-18 21:17 --------- d-----w c:\program files\Easy iPod MP4 PSP 3GP
2009-01-18 21:10 --------- d-----w c:\documents and settings\All Users\Application Data\VUG
2009-01-16 18:14 --------- d-----w c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-01-07 12:22 --------- d-----w c:\documents and settings\LocalService\Application Data\agi
2009-01-07 12:21 339,968 ----a-w c:\windows\system32\pythoncom25.dll
2009-01-07 12:21 2,117,632 ----a-w c:\windows\system32\python25.dll
2009-01-07 12:21 114,688 ----a-w c:\windows\system32\pywintypes25.dll
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-04 14:17 68 -c--a-w c:\documents and settings\celine\Application Data\wklnhst.dat
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 11:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2008-03-16 13:30 216,064 --sh--r c:\windows\system32\nbDX.dll
2008-08-22 13:06 16,384 -csha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-08-22 13:06 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008082220080823\index.dat
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2007-08-04 190024]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-12-16 94208]
"GTGMOUSE"="c:\program files\Omni\OmniMouse driver\10.0\GTGMouse.exe" [2007-04-10 482304]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-28 77824]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]

c:\documents and settings\celine\Menu D‚marrer\Programmes\D‚marrage\
MSN Pictures Displayer.lnk - c:\program files\MSN Pictures Displayer\MSN Pictures Displayer.exe [2009-01-22 4708864]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-08-16 303104]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.dvsd"= dvc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\eChanblard\\emule.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22331:TCP"= 22331:TCP:emuletcp
"49923:TCP"= 49923:TCP:emuleudp

R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\drivers\tffsport.sys [2007-08-05 149376]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-06 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-05-06 20560]
S3 fcdr4_xp;fcdr4_xp;\??\c:\docume~1\celine\LOCALS~1\Temp\fcdr4_xp.sys --> c:\docume~1\celine\LOCALS~1\Temp\fcdr4_xp.sys [?]
S3 qdmload;qdmload;\??\c:\docume~1\celine\LOCALS~1\Temp\qdmload.sys --> c:\docume~1\celine\LOCALS~1\Temp\qdmload.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0eae6e3-ed0d-11dc-acee-00038a000015}]
\Shell\AutoRun\command - usdeiect.com
\Shell\explore\Command - usdeiect.com
\Shell\open\Command - usdeiect.com
.
Contenu du dossier 'Tâches planifiées'

2007-12-27 c:\windows\Tasks\Microsoft_Hardware_Launch_setup_exe.job
- D:\setup.exe []

2009-02-20 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
- - - - ORPHELINS SUPPRIMES - - - -

WebBrowser-{A057A204-BACC-4D26-969A-2AB983EE729B} - (no file)


.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mWindow Title =
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: { - c:\program files\Messenger\msmsgs.exe
TCP: {4B194A0D-D7B5-4573-B482-4B0C3411C337} = 192.168.1.1
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-20 18:01:48
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(600)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-02-20 18:04:10
ComboFix-quarantined-files.txt 2009-02-20 17:04:07

Avant-CF: 38 592 622 592 octets libres
Après-CF: 38,889,799,680 octets libres

WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

194 --- E O F --- 2009-02-11 09:36:57
0
Profil bloqué
20 févr. 2009 à 18:06
raport hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:06:00, on 20/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [GTGMOUSE] "C:\Program Files\Omni\OmniMouse driver\10.0\GTGMouse.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - https://www.epson.eu/support/
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B194A0D-D7B5-4573-B482-4B0C3411C337}: NameServer = 192.168.1.1
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
0